CVE-2026-56780 Details
Description
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can bypass object-level access controls to reset superadmin passwords and achieve full account takeover.
A vulnerability allowing insecure direct object reference has been identified in Modoboa versions prior to 2.9.0. This vulnerability exists in the PUT /api/v1/accounts/{pk}/password/ endpoint, where domain administrators can change any user's password. Exploitation of this flaw allows domain admins to bypass object-level access controls, enabling them to reset superadmin passwords and gain full account access.
Users are advised to update to Modoboa version 2.9.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 29, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/modoboa/modoboa/commit/a1878c4920a6e47c3217c6ff1ed4a8753c202661 | [email protected] | Source CodeVendor |
| https://github.com/modoboa/modoboa/pull/4038 | [email protected] | Issue TrackingVendor |
| https://www.vulncheck.com/advisories/modoboa-insecure-direct-object-reference-in-account-password-change-api | [email protected] | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Modoboa | < 2.9.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 29, 2026 | New CVE Received | [email protected] |
Volerion